Expand description
The recommendation object (OMS 0x0C), the deterministic summary renderer, the dedup key, and the lifecycle state machine + audit records.
Invariants enforced here:
- Analyzers emit a
(template_id, args)summary, never free prose. dedup_key,origin, and the params snapshot are engine-stamped.dedup_keyexcludes proposal content and the/majorversion, so a growing cluster or an analyzer upgrade does not re-propose as novel — for ANALYZER findings. An authored (origin = llm) executable proposal keys on a fingerprint of its content as well, because there the content IS the finding: two different lessons on one entity are two findings, and the same lesson re-authored is one.- Lifecycle transitions are gated;
pending → appliedis policy-only.
Structs§
- Audit
Record - One immutable audit Observation per transition, hash-chained per recommendation.
- Gating
Evidence - The recorded evalset-run edge (§7.4): what an apply of a code revision must present, and what its audit Observation carries. “Trust me, it passed” is not an edge; (evalset, run, stats) is.
- Metric
Snapshot - A reproducible metric snapshot; powers outcome review.
- Outcome
Result - A measured outcome for an applied recommendation at one checkpoint — the
Verify gate’s output.
held= the metric did not regress at this horizon;regressed= it got worse (a revert is proposed). A recommendation accumulates one of these per horizon, forming a time series. - RecDraft
- What an analyzer emits.
dedup_key,origin, and the params snapshot are not here — the engine stamps them. Non-exhaustive so the engine can add fields without breaking analyzers. - Recommendation
- A stored recommendation.
hash(the content address) andstatus(the index-layer cache) are set by the engine, not serialized into the grain body — the body is immutable content, the lifecycle lives in the state index and the audit chain. - Summary
- A deterministic, template-rendered summary. The analyzer chooses a
template_idand suppliesargs; the text is produced here, so an analyzer can never emit arbitrary prose into the queue.
Enums§
- Checkpoint
- When an applied recommendation is re-measured — one checkpoint of the Verify gate’s schedule, in the unit the deployment actually counts in.
- Observer
Type - Who/what performed a transition.
- Proposal
- The proposed change. Exactly one variant per recommendation.
- RecStatus
- Lifecycle status — a rebuildable index-layer cache (the recommendation’s content hash is stable for its whole life).
Constants§
- MAX_
BECAUSE - Maximum length of a BECAUSE reason.
- MAX_
EVIDENCE - Maximum representative evidence hashes carried inline (proposal §7.1).
Functions§
- authored_
dedup_ key - The dedup key of an AUTHORED executable proposal:
dedup_keyplus a fingerprint of the proposal’s content. An analyzer finding is “this target has this kind of problem”, so content is rightly excluded; an authored lesson is “do this”, and two different lessons on the same entity must both reach the queue while the same lesson re-authored must not. The fingerprint is over the normalized text — case-folded, non- alphanumerics dropped, whitespace collapsed — so a rewording that changes no word is the same lesson and one that changes a word is a new one (a semantic near-duplicate is the reviewer’s call, not this key’s). - content_
fingerprint - Sixteen hex chars of FNV-1a (64-bit) over the normalized content. A dedup key needs stability and spread, not cryptographic strength — a collision here would merge two findings in a review queue, never grant anything — so this stays dependency-free, as the crate is by policy.
- dedup_
key - Compute the dedup key:
family ⟂ target_ref ⟂ action_kind, case-folded. Excludes proposal content and evidence by construction. - is_
regression - The one regression rule.
- revert_
dedup_ key - The dedup key of a REVERT:
dedup_keyplus the hash of the applied recommendation it retracts. An analyzer finding is “this target has this kind of problem”, so two findings on one target rightly collapse — but a revert is about one specific applied recommendation, and two lessons on the same entity that both regressed need two reverts. Until 2026-09-06 they shared a key and the second was dropped as a duplicate of the first (crates/areev-bench/CURVE.md, seed 3: two regressed, one revert). - validate_
code_ rules - Rule E1’s structural checks (§7.4), applied when a draft is stamped and re-checked when a stored grain is loaded (a hand-authored grain must not bypass the rule):